The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Qualcomm Android Zero-Day Exploited in 2026
In March 2026, Google disclosed a high-severity vulnerability, CVE-2026-21385, affecting Qualcomm's open-source display driver used in Android devices. This integer overflow flaw leads to memory corruption when processing user-supplied data without proper buffer size validation. The vulnerability was reported to Qualcomm on December 18, 2025, and patches were included in the March 2026 Android security update. Google noted indications of limited, targeted exploitation of this zero-day vulnerability in the wild. The March 2026 Android security bulletin addressed a total of 129 vulnerabilities, including this actively exploited flaw. The presence of an actively exploited zero-day vulnerability underscores the critical need for timely security updates. Organizations and individuals should prioritize applying the March 2026 security patch to mitigate potential risks associated with this and other vulnerabilities addressed in the update.
6 months ago
Kill Chain
Silver Dragon 2026: Unveiling APT41's Covert Cyberespionage Tactics
In mid-2024, the Chinese state-sponsored group Silver Dragon, associated with APT41, initiated cyberespionage campaigns targeting government organizations across Southeast Asia and Europe. The group gained initial access through exploiting public-facing servers and phishing emails containing malicious attachments. To maintain persistence, Silver Dragon hijacked legitimate Windows services, allowing their malware to blend seamlessly with normal system activities. They deployed custom tools like GearDoor, which utilized Google Drive for covert command-and-control communications, SSHcmd for remote access, and SliverScreen for capturing user activity screenshots. ([research.checkpoint.com](https://research.checkpoint.com/2026/silver-dragon-targets-organizations-in-southeast-asia-and-europe/?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored threat actors who are increasingly leveraging trusted cloud services and legitimate system processes to evade detection. The use of such sophisticated methods highlights the need for organizations to enhance their cybersecurity measures and remain vigilant against advanced persistent threats. ([research.checkpoint.com](https://research.checkpoint.com/2026/silver-dragon-targets-organizations-in-southeast-asia-and-europe/?utm_source=openai))
6 months ago
Kill Chain
INTERPOL's Operation Sentinel: A Landmark Cybercrime Crackdown in Africa
Between October 27 and November 27, 2025, INTERPOL coordinated Operation Sentinel, a significant cybercrime crackdown across 19 African countries. The operation led to the arrest of 574 suspects involved in business email compromise (BEC), digital extortion, and ransomware attacks. Authorities dismantled over 6,000 malicious links, decrypted six ransomware variants, and recovered approximately USD 3 million. The cases investigated were linked to estimated financial losses exceeding USD 21 million. Notable incidents included a thwarted USD 7.9 million BEC attempt targeting a petroleum company in Senegal and a ransomware attack in Ghana that encrypted 100 terabytes of data, with nearly 30 terabytes successfully recovered. ([interpol.int](https://www.interpol.int/es/Noticias-y-acontecimientos/Noticias/2025/574-arrests-and-USD-3-million-recovered-in-coordinated-cybercrime-operation-across-Africa?utm_source=openai)) This operation underscores the escalating threat of cybercrime in Africa, with online offenses now accounting for a significant proportion of all crimes in many regions. The success of Operation Sentinel highlights the effectiveness of international collaboration in combating cyber-related offenses and the critical need for continued vigilance and cooperation to protect critical infrastructure and sensitive data. ([interpol.int](https://www.interpol.int/es/Noticias-y-acontecimientos/Noticias/2025/574-arrests-and-USD-3-million-recovered-in-coordinated-cybercrime-operation-across-Africa?utm_source=openai))
6 months ago
Kill Chain
Coruna Exploit Kit: Unveiling the First Mass-Scale iOS Attack
In early 2026, security researchers uncovered the 'Coruna' exploit kit, a sophisticated suite of hacking tools capable of compromising iPhones running older iOS versions. Initially identified in February 2025 during a surveillance vendor's attempt to deploy spyware on behalf of a government client, Coruna was later observed in attacks targeting Ukrainian users by a Russian espionage group and subsequently by financially motivated hackers in China. The exploit kit chains together multiple vulnerabilities, allowing attackers to bypass iOS defenses and gain full control over targeted devices. ([techcrunch.com](https://techcrunch.com/2026/03/03/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals/?utm_source=openai)) The proliferation of Coruna underscores the risks associated with the leakage of advanced cyber tools originally developed for government use. Similar to the EternalBlue exploit that fueled the WannaCry and NotPetya attacks in 2017, Coruna's widespread availability has enabled various threat actors to conduct mass-scale attacks on iOS devices, affecting at least 42,000 devices to date.
6 months ago
Kill Chain
Perplexity Comet Browser's 'PleaseFix' Vulnerabilities Expose Critical Security Flaws
In March 2026, Zenity Labs disclosed critical vulnerabilities in Perplexity's AI-powered Comet browser, collectively termed 'PleaseFix.' These flaws allowed attackers to exploit indirect prompt injections, enabling unauthorized access to local files and credential theft without user interaction. By embedding malicious prompts in trusted content, such as calendar invites, attackers could manipulate the AI agent to perform unauthorized actions, including exfiltrating sensitive data and compromising password managers like 1Password. Perplexity addressed these vulnerabilities following responsible disclosure, implementing fixes to prevent autonomous access to local file systems and unauthorized credential manipulation. This incident underscores the inherent security challenges in agentic AI systems, highlighting the need for robust safeguards against prompt injection attacks and the importance of continuous monitoring and updating of AI-driven applications to mitigate emerging threats.
6 months ago
Kill Chain
CyberStrikeAI: The AI Tool Empowering Hackers in 2026
In early 2026, cybersecurity researchers identified that threat actors had adopted CyberStrikeAI, an open-source AI-native security testing platform, to automate and enhance their cyberattacks. This tool integrates over 100 security tools with an intelligent orchestration engine, enabling end-to-end automation from vulnerability discovery to attack-chain analysis. Notably, the same infrastructure used in a campaign that breached over 500 Fortinet FortiGate firewalls was observed running CyberStrikeAI, indicating its role in facilitating these attacks. The adoption of AI-powered tools like CyberStrikeAI by cybercriminals signifies a shift towards more sophisticated and automated attack methodologies. This trend underscores the urgent need for organizations to bolster their defenses against AI-driven threats, as traditional security measures may become increasingly inadequate.
6 months ago
Kill Chain
Android 2026 Security Update Addresses Exploited Qualcomm Zero-Day
In March 2026, Google released a security update addressing 129 vulnerabilities in Android devices, notably including CVE-2026-21385—a high-severity zero-day flaw in Qualcomm's display component. This integer overflow vulnerability allows local attackers to cause memory corruption, potentially leading to unauthorized control over affected devices. The flaw impacts 234 Qualcomm chipsets, and there are indications of its limited, targeted exploitation in the wild. ([cyberscoop.com](https://cyberscoop.com/android-security-update-march-2026/?utm_source=openai)) The active exploitation of CVE-2026-21385 underscores the persistent threat posed by zero-day vulnerabilities in widely used hardware components. Organizations must prioritize timely patch management and maintain robust security protocols to mitigate risks associated with such vulnerabilities.
6 months ago
Kill Chain
Cloud Imperium Games Data Breach: A Wake-Up Call for the Gaming Industry
In January 2026, Cloud Imperium Games (CIG), the developer behind 'Star Citizen,' experienced a sophisticated cyberattack resulting in unauthorized access to backup systems containing user data. The breach, discovered on January 21, exposed personal information including names, contact details, usernames, and dates of birth. Notably, financial information and passwords remained secure. CIG addressed the intrusion promptly, implementing enhanced security measures to prevent further incidents. ([theregister.com](https://www.theregister.com/2026/03/03/brit_games_studio_cloud_imperium/?utm_source=openai)) This incident underscores the critical importance of timely breach disclosure and robust data protection practices in the gaming industry. The delayed notification has raised concerns about transparency and user trust, highlighting the need for companies to adhere to regulatory requirements and maintain open communication with their user base. ([scworld.com](https://www.scworld.com/brief/cloud-imperium-faces-backlash-over-delayed-data-breach-disclosure?utm_source=openai))
6 months ago
Kill Chain
AWS Data Centers in Middle East Damaged by Drone Strikes
In early March 2026, Amazon Web Services (AWS) experienced significant disruptions after drone strikes targeted its data centers in the Middle East. Two facilities in the United Arab Emirates (UAE) were directly hit, while a third in Bahrain sustained damage from a nearby strike. These attacks resulted in structural damage, power outages, and water damage due to fire suppression efforts, leading to elevated error rates and degraded availability for services such as Amazon EC2, Amazon S3, and Amazon DynamoDB. AWS is collaborating with local authorities to restore services, but recovery is expected to be prolonged due to the extent of the physical damage. This incident underscores the vulnerability of critical cloud infrastructure to physical attacks, especially in regions experiencing geopolitical tensions. Organizations relying on cloud services are reminded of the importance of robust disaster recovery plans and the need to consider geographic redundancy to mitigate risks associated with localized disruptions.
6 months ago
Kill Chain
LexisNexis Data Breach: A Wake-Up Call for Third-Party Platform Security
In December 2024, LexisNexis Risk Solutions experienced a data breach when an unauthorized party accessed data stored on GitHub, a third-party platform used for software development. The breach, discovered in April 2025, exposed personal information of over 364,000 individuals, including names, contact details, Social Security numbers, driver's license numbers, and dates of birth. The company has since notified affected individuals and offered two years of complimentary identity protection and credit monitoring services. This incident underscores the critical importance of securing third-party platforms and the potential risks associated with their use. Organizations must ensure robust security measures are in place to protect sensitive data, especially when utilizing external services for development purposes.
6 months ago
Kill Chain
The Rising Threat of Compromised cPanel Credentials in Cybercrime Markets
In March 2025, a cybercriminal known as "miya" advertised for sale compromised SSH, cPanel, Mail, and WebHost Manager (WHM) credentials belonging to a Canadian car dealership on a dark web forum, pricing the access at $400. These credentials provided potential attackers with privileged access to the dealership's critical systems, including remote command-line server control via SSH, administrative capabilities through WHM and cPanel, and access to sensitive communications via the mail server. The breach underscored the escalating cybersecurity risks faced by automotive retailers, who increasingly rely on interconnected digital systems to manage sales, customer data, and backend infrastructure. ([cyberpress.org](https://cyberpress.org/cybercriminal-miya-stolen/?utm_source=openai)) This incident highlights a broader trend of cybercriminals targeting cPanel and other site management credentials to facilitate unauthorized access to web servers and associated services. The sale of such credentials on underground forums has become increasingly common, with prices ranging from $3 to $5, depending on the target and level of access provided. ([documents.trendmicro.com](https://documents.trendmicro.com/assets/wp/wp-north-american-underground.pdf?utm_source=openai))
6 months ago
Kill Chain
Chrome's 2026 Vulnerability: A Wake-Up Call for Browser Security
In January 2026, a high-severity vulnerability (CVE-2026-0628) was identified in Google Chrome's WebView component, allowing attackers to escalate privileges via malicious extensions. This flaw, present in versions prior to 143.0.7499.192, enabled unauthorized script or HTML injection into privileged pages, potentially granting access to sensitive resources. Google promptly addressed the issue by releasing a patch on January 7, 2026. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-0628?utm_source=openai)) The incident underscores the critical importance of timely software updates and vigilant extension management. As browser vulnerabilities continue to be a prime target for cyber threats, organizations must prioritize regular patching and educate users on the risks associated with unverified extensions to mitigate potential security breaches.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports